PT-2026-29864 · Openproject · Openproject

Ochk0

·

Published

2026-04-02

·

Updated

2026-04-03

·

CVE-2026-34717

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenProject versions prior to 17.2.3
Description OpenProject, a web-based project management software, has an issue where user input is directly embedded into SQL WHERE clauses without proper parameterization. This occurs due to the =n operator in modules/reporting/lib/report/operator.rb:177. This could allow for SQL injection. The issue affects authenticated users and could potentially grant them database access.
Recommendations Update to version 17.2.3 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34717

Affected Products

Openproject